ISO 27001 Program Build-out End‑to‑end ISO 27001 implementation, from gap analysis and risk assessment to ISMS documentation and successful certification. iso27001 risk isms Live Code
SOC 2 Readiness and Evidence Automation Designed SOC 2 controls and automated evidence collection across CI/CD, cloud, and HR systems to reduce audit prep time. soc2 automation audit Live Code
Vendor Risk Management (TPRM) Built a third‑party risk process with intake forms, risk tiers, and continuous monitoring for critical vendors. tprm governance risk Live Code
Secure SDLC Enablement Introduced threat modeling, SAST/DAST, and security gates in pipelines; shipped developer playbooks and training. ssdcl devsecops appsec Live Code
Policies and Awareness Program Authored policy suite (AUP, Access Control, Cryptography, BYOD, Incident Response) and delivered engaging awareness campaigns. policies awareness training Live Code